Network sniffer

Wireshark display and capture filters

Wireshark Filters: Display vs Capture

A common thought by beginners when it comes to Wireshark filters is that display and capture filters do the same thing. Well, they don’t; they may seem to be doing the same thing to you but the difference is when the packets get filtered.

Display filters don’t stop Wireshark from capturing any packets, you still capture all packets but it only displays you the packets you asked for. While capture filters when used make it so Wireshark won’t capture any packets that you have specified not to.

Wireshark Filters

 

Wireshark

Wireshark Basic Overview

What is Wireshark?

Wireshark is open source software for Windows and UNIX/Linux, open source meaning that anyone can download it for free and can if they want alter the source code however they please. It’s considered the best network packet analyzer you can use today.

But, What is a network packet analyzer?

A network packet analyzer captures network packets on a specified network and would then display very detailed data about the network protocols of each packet.

Typical users are:

Network administrators- who can use it to troubleshoot network issues

Cyber Security Engineers- Can watch and see any attempted attacks on a network

Developers- to Debug protocols

Wireshark Logo

 

For more information check out

https://www.wireshark.org/

 

 

Check out our post on display filters and capture filtersĀ